On August 25, the co-founder of Natoma, now part of Snowflake, and the team at Trust3 AI are getting in a room with data & AI practitioners in Menlo Park to answer one question: How do leading teams discover, observe, and secure every agent in production? If you’re interested in the topic, you might be wondering about Trust3 AI and Snowflake on August 25th: Who’s Governing Your Agents?
Everyone is racing to deploy AI agents. Almost nobody can answer the question that decides whether it is safe: what is that agent allowed to touch?
Paresh Bhaya, who co-built the enterprise MCP gateway Snowflake acquired, will open the technical case. Matthew Sullivant, Sr Product Manager at Trust3 AI, will walk through AgentDOS, the control plane for discovering, observing, and securing agents across any data source. The team will run a live demo of Policy Agent on Snowflake and showcase how you can use plain-english (natural language) to create policies. Here are some pain points that we will address.
You can’t count the agents you have, let alone govern them.
Ask your platform team how many agents are running in production. In most cases, they either don’t know or will give you a wrong number, by a multiple.
The agents your teams know about are the ones someone registered and put on a slide. The ones doing the damage are the copilot spun up inside a SaaS tool, the script wired to an internal API last quarter, the helper an engineer stood up and never decommissioned. They hold real credentials. They touch real data. Most enterprises undercount them three to ten times over.
You cannot write a policy for an agent you do not know exists. So discovery comes first, and it has to be automatic, continuous, and indifferent to which framework or cloud the agent was built on. The registry you maintain by hand is already out of date.
The new focus is about who governs the agents.
For two years enterprise AI was about the models: whose is largest, cheapest, longest context. The real question now is who controls the layer that decides what agents know, what they do, and what they are allowed to touch.
Your agents do not live inside one platform. They cross Snowflake, Databricks, SaaS apps, internal APIs, and increasingly each other, talking over MCP at machine speed. A control layer that stops at a vendor boundary is a fence around one field while the herd roams the property. Knowing an agent exists tells you nothing about what it did at 2 AM last Tuesday. You need to observe every tool call, every data touch, every handoff between agents, continuously and across systems.
Paresh will make the case for governing agents from the data layer up, across systems rather than inside one.
Roles tell you who. Agents need to be governed by why.
Traditional authorization asks one question: does this identity have permission for this resource? That breaks for agents!
The same service principal might be cleared to query a customer table for sales forecasting and forbidden from querying it to extract personal data. Same identity, same table, different purpose, opposite answers. Roles cannot see the difference.
This is where securing agents departs from securing models. The risk shifts from output to action. The question is no longer whether an answer is correct. It is what the agent is allowed to do, and whether anyone can stop it in time. Observability tells you what happened. Security means acting on it before it happens: access scoped to the agent’s declared purpose, checked the moment a request is made, before any data moves.
Watch a plain-English policy govern an agent live.
Paresh’s gateway governs how agents connect. Policy Agent governs what they can reach once they are in, at the data itself. This is where Matthew introduces Trust3’s approach to fine-grained access control at the data layer, and shows it live on Snowflake: write an access policy in plain-English (natural language), watch Policy Agent turn it into the underlying roles and grants and apply them automatically, then watch that same policy govern what an agent is allowed to touch. No hand-written SQL, no manual role wrangling. You state the intent, the enforcement follows.
The evening closes with open Q&A across all the speakers, then food, drinks, and time to compare notes with people solving the same problem.
The agents are already running. The question is whether you can discover them, observe what they do, and secure every action before it executes.
